[openstack-dev] [tripleo] becoming third party CI

Clark Boylan cboylan at sapwetik.org
Mon Mar 21 21:17:03 UTC 2016


On Mon, Mar 21, 2016, at 05:33 AM, Derek Higgins wrote:
> Doing this in 3rd party ci I think simplyfies things because we'll no
> longer need a public cloud and as a result the security measures
> requeired to avoid putting cloud credentials on the jenkins slaves
> wont be needed.

Just a word of warning that if you run arbitrary code posted to Gerrit
and post log results that are publicly available then you probably want
to avoid putting any credentials or other secret data on the Jenkins
slaves as that can be trivially exposed (assuming the jobs allow root to
do tripleo things like build dib images).

Clark



More information about the OpenStack-dev mailing list